US Seizes Domains Behind Two Chinese-Linked Hacking Tools Used Against Critical Infrastructure
The US Justice Department and FBI have seized domain names for two hacking tools linked to the Chinese government-connected group Flax Typhoon. The tools are Microscan, which scans for vulnerabilities, and FishHub, a spearphishing tool. Both were created by Integrity Technology Group, a China-based company the US sanctioned last year and previously accused of being behind a large botnet. The seizures were court-authorised in the Western District of Pennsylvania, and are intended to deny hackers access to the tools.
The FBI, CISA and the NSA also released a joint advisory. It says the actors combine automated scanning, large-scale botnets and hands-on exploitation to steal sensitive data. Methods named include cross-site scripting attacks and password spraying on Microsoft Exchange servers, persistence through VPN software, and the use of scripts to take emails and credentials. Law enforcement said Integrity Tech used a Mirai-variant botnet of internet-connected devices to support Microscan.
Reported Microscan targets include a South Carolina power company, airports in Japan and Poland, and critical infrastructure firms and universities in Taiwan. FishHub, which installs malware after a victim is phished, has hit Taiwanese universities. CISA's Chris Butera said Chinese government-affiliated actors continue to position themselves inside critical infrastructure networks, including operational technology systems, with the aim of disrupting critical functions at a future time of their choosing.